General Data Protection Regulation

storm-tern is committed to protecting your privacy and ensuring compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

Legal Basis for Processing

We process your personal data under the following legal bases:

  • Contract Performance: Processing necessary to provide photo restoration services you have requested
  • Consent: Where you have given explicit consent for specific processing activities
  • Legitimate Interests: For improving our services and communicating about service delivery

Your Rights Under GDPR

You have the following rights regarding your personal data:

Right to Access

You have the right to request a copy of the personal information we hold about you, including details about how we process your data.

Right to Rectification

You may request correction of any inaccurate or incomplete personal information we hold about you.

Right to Erasure

You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.

Right to Restrict Processing

You may request that we limit the processing of your personal data in specific situations.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format.

Right to Object

You may object to the processing of your personal data in certain circumstances.

Right to Withdraw Consent

Where processing is based on consent, you have the right to withdraw that consent at any time.

Data Protection Officer

For any questions regarding data protection or to exercise your rights, please contact us at [email protected].

Data Transfers

Your personal information is stored and processed in Canada. We do not transfer personal data outside of Canada.

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including any legal, accounting, or reporting requirements.

Security Measures

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of data in transit and at rest
  • Access controls and authentication procedures
  • Regular security assessments
  • Staff training on data protection

Automated Decision Making

We do not use automated decision-making or profiling in our processing of your personal data.

Complaints

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the relevant supervisory authority.

Updates to This Policy

We may update this GDPR compliance statement to reflect changes in our practices or applicable regulations. Any updates will be posted on this page.

Last Updated: June 23, 2026